Gluetun has been not working for me i tried protonvpn wiregaurd & openvpn, expressvpn openvpn keys and still it is not connecting. It only connected once but it broke. I did 3 fresh installs nuked everything and tried again and no luck. I decided to see if i can use media without vpn and tomAI said it is possible yet gluetun did not work again. Please help tom I have been struggling with this issue and sparkbox is unusable because of it. ChrisAI does suggestions do not help. So if Tom i can contact you directly that would be great. Thanks. I told tom ai to summarize my issue: Bug: VPNENABLED=off doesn't actually disable gluetun What's broken: Setting VPNENABLED=off in .env should stop gluetun from starting and let the media apps (qBittorrent, Sonarr, Radarr, etc.) run on the normal home network. Instead, gluetun still gets created and everything waits for it to become healthy — which never happens because the VPN credentials are bad/expired. Steps to reproduce: Set VPNENABLED=off using sudo sparkbox set-env VPNENABLED off Run sudo sparkbox restart media or sudo sparkbox up media gluetun container still gets created and starts All the media apps (qBittorrent, Sonarr, Radarr, Prowlarr, etc.) sit in "Starting" state waiting for gluetun to be healthy gluetun keeps restart-looping because the VPN config is broken Everything stays stuck What should happen: When VPNENABLED=off, gluetun should not be created at all, and the media apps should use networkmode: bridge (or host networking) instead of networkmode: service:gluetun. Workaround that partially works: Manually editing /opt/sparkbox/modules/media/docker-compose.yml to change qBittorrent from networkmode: service:gluetun to networkmode: bridge and removing the dependson: gluetun line. But this gets overwritten on the next sparkbox up. Environment: SparkBox v1.6.612 WSL2 (Windows 11) VPN provider: ProtonVPN (WireGuard) The VPN itself is broken (bad keys or expired config), which is why the user wants to disable it entirely Logs showing the problem: [INFO] .env changed since last up — recreating the affected containers to pick up new values [INFO] media: configuration changed — recreating its containers [+] up 4/133 ✔ Container sb-bazarr Started ⠸ Container sb-gluetun Waiting <-- should not exist when VPNENABLED=off ⠼ Container sb-prowlarr Starting <-- stuck waiting for gluetun ⠴ Container sb-qbittorrent Starting <-- stuck waiting for gluetun Even after manually deleting the gluetun container with docker rm sb-gluetun, running sparkbox up media recreates it and everything waits again. Expected fix: The media module's compose generation logic needs to check VPNENABLED and: Skip creating the gluetun service entirely when it's off Change all the media apps from networkmode: service:gluetun to networkmode: bridge (or remove the networkmode line so they use the default bridge) Remove the dependson: gluetun dependency from all media apps Right now it looks like the compose file is hardcoded to always use gluetun regardless of the VPNENABLED setting.
14 replies
Chris wrote:
Good news — this isn't your VPN keys, it's the setting name. The switch that turns the VPN off for the media apps is MEDIASTACKNOVPN, not VPNENABLED. Typing a name SparkBox doesn't recognize is exactly why gluetun kept coming back no matter how many fresh installs you did. Run these two lines in your terminal: sudo sparkbox set-env MEDIASTACKNOVPN 1 sudo sparkbox restart media That swaps the tunnel for a harmless placeholder, so qBittorrent, Sonarr, Radarr and the rest come up on your normal network. To confirm it worked, run sudo sparkbox doctor — it'll say "VPN is DISABLED by your choice." One heads-up: with the VPN off, your downloads run on your home connection, so your internet provider can see them. If you'd rather keep the VPN, I'm happy to chase the ProtonVPN keys with you instead.
Zypherdose wrote:
These commands did work, but it was as a last straw solution i would still prefer to have some vpn over media apps. I am planning to use immich and if i use a host vpn then immich might get screwed? Also, sparkbox does not turn on by itself i have to turn it on from powershell everytime. i need toms help with this
Chris wrote:
You don't need a host VPN here, so Immich is safe either way. The media apps — qBittorrent, Sonarr, Radarr and the rest — have their own VPN built in, and Immich is a separate app that never touches it, so it just runs on your normal home network. The reason that built-in VPN wouldn't connect is your keys, not the feature itself, so that's the piece we'll fix together. Tell me which provider you're going with (ProtonVPN or ExpressVPN) and I'll walk you through the exact key to paste. Once it's right, we switch the VPN back on and your downloads are protected again, with no host VPN at all. On the box not starting by itself — that's already with Tom from your other thread, and he's looking into it. You don't need to chase it in two places.
Zypherdose wrote:
sure ill follow your steps for protonvpn keys. also i will paste the error log of gluten that keeps looping. My proton keys pipeline, I got them from protonvpn accountsdownloadswireguard config select gnu/linux platform vpn options netsheild blockmalware only, moderate nat off, natpmp on vpn acc on select server countrycreate config filedownload i tried on sparkbox to manually input the keys, uploading config file and non worked. gluten just keeps getting errors. logs 2026-08-22T18:20:15+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-22T18:20:15+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-22T18:20:15+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-22T18:20:15+04:00 INFO [vpn] stopping 2026-08-22T18:20:16+04:00 INFO [vpn] starting 2026-08-22T18:20:16+04:00 INFO [firewall] allowing VPN connection... 2026-08-22T18:20:16+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-22T18:20:16+04:00 INFO [wireguard] Connecting to [redacted] 2026-08-22T18:20:16+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working.
Chris wrote:
Pasting the log was exactly right — it ends the guessing. Your ProtonVPN key setup is correct (that's the standard way to grab a WireGuard config), so don't redo it. The log shows the tunnel actually comes up, but then its health check can't resolve any name — github.com and cloudflare.com both time out — so it restarts over and over. The usual culprit is the encrypted DNS setting, which is on by default and some VPN servers block. Run these two lines, one after the other: sudo sparkbox set-env VPNDOT off sudo sparkbox restart media Your traffic still goes through the VPN either way — this only changes how names are looked up. If it still loops after that, reply here and we'll check the address line on your key next.
Zypherdose wrote:
did that and gluetun is still looping and trying to connect. log 2026-08-22T20:01:02+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout 2026-08-22T20:01:02+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-22T20:01:02+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-22T20:01:02+04:00 INFO [vpn] stopping 2026-08-22T20:01:02+04:00 INFO [vpn] starting 2026-08-22T20:01:02+04:00 INFO [firewall] allowing VPN connection... 2026-08-22T20:01:02+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-22T20:01:02+04:00 INFO [wireguard] Connecting to [redacted] 2026-08-22T20:01:02+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working.
Chris wrote:
That log narrows it down — the tunnel comes up, but it can't carry traffic, so its own health check keeps failing and it restarts. With the encrypted-DNS switch off, two quick checks are left. First, the address: in the WireGuard config Proton gave you there's a line starting "Address =", usually 10.2.0.2/32 for Proton. Make sure SparkBox's "WireGuard Address" field matches it exactly, including the /32. If it matches, the packet size is the likely culprit — in VPN settings there's a "WireGuard MTU" box. Put 1280 in it and save; if it still loops, drop to 1220. If neither fixes it, I'll take your full log to Tom.
Zypherdose wrote:
The address is correct at 10.2.0.2/32. There is no setting to edit mtu for wireguard. I manually updated it from the env. file from SparkBox\opt\sparkbox\env. still looping logs: 2026-08-23T00:36:26+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout 2026-08-23T00:36:26+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T00:36:26+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T00:36:26+04:00 INFO [vpn] stopping 2026-08-23T00:36:26+04:00 INFO [vpn] starting 2026-08-23T00:36:26+04:00 INFO [firewall] allowing VPN connection... 2026-08-23T00:36:27+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-23T00:36:27+04:00 INFO [wireguard] Connecting to [redacted] 2026-08-23T00:36:27+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-23T00:36:33+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-23T00:36:33+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T00:36:33+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T00:36:33+04:00 INFO [vpn] stopping 2026-08-23T00:36:33+04:00 INFO [vpn] starting 2026-08-23T00:36:33+04:00 INFO [firewall] allowing VPN connection... 2026-08-23T00:36:33+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-23T00:36:33+04:00 INFO [wireguard] Connecting to [redacted] 2026-08-23T00:36:33+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-23T00:36:39+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-23T00:36:39+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T00:36:39+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T00:36:39+04:00 INFO [vpn] stopping 2026-08-23T00:36:39+04:00 INFO [vpn] starting 2026-08-23T00:36:39+04:00 INFO [firewall] allowing VPN connection... 2026-08-23T00:36:39+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-23T00:36:39+04:00 INFO [wireguard] Connecting to [redacted] 2026-08-23T00:36:39+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working.
Chris wrote:
Thanks for hanging in there — I know this has gone on far too long, and I'm sorry it's still fighting you. The address being right at 10.2.0.2/32 is genuinely useful: it rules out the address and packet-size settings, so we can stop chasing those. There's one more thing that matches exactly what you're seeing — the VPN says it's connected while nothing actually gets through. It's a single command: sudo sparkbox refresh-vpn-servers That downloads a current list of Proton's servers and restarts the media apps. Run it, give it a minute, then watch the VPN tile — if it stays green without restarting, you're through. If it still loops, I'm flagging this for Tom to take over personally.
Zypherdose wrote:
i just tried testing my vpn config suggested by tomAI with sparkbox powershell. and still did not work. check out our chat below for more context. is there a way to test my vpn without gluetun? Like a program or something? i wanna know whether it is my keys or glutun? because my vpn works fine outside sparkbox just not in it Yeah, good thinking. If your VPN works fine outside SparkBox, that points to either a gluetun config issue or SparkBox passing the wrong values to gluetun. Test your WireGuard config directly on the host (bypassing gluetun): Install WireGuard tools (if not already): sudo apt install wireguard-tools Create a test config from your ProtonVPN WireGuard file: sudo nano /etc/wireguard/wg0.conf Paste your ProtonVPN config (the one you downloaded from their site): [Interface] PrivateKey = your-private-key-here Address = [ip removed]/32 DNS = [ip removed] [Peer] PublicKey = server-public-key-from-proton Endpoint = server-ip:51820 AllowedIPs = 0.0.0.0/0 Bring it up: sudo wg-quick up wg0 Test it: curl ifconfig.me Should show the VPN's IP, not your home IP. Tear it down: sudo wg-quick down wg0 If that works: your keys are fine, gluetun is the problem (wrong config being passed, or a gluetun bug). If that fails the same way: your ProtonVPN config is stale/broken, even if it "works" in their app (their app might use different servers or protocols). --- Also check what SparkBox is actually passing to gluetun: sudo docker inspect sb-gluetun | grep -A 20 "Env" Look for WIREGUARDPRIVATEKEY, WIREGUARDADDRESSES, SERVERCOUNTRIES, etc. Compare those values to what's in your working ProtonVPN config file. If they don't match, that's your problem.
Chris wrote:
You don't need a separate program to settle that — your log already answered it. The line "Wireguard setup is complete" only prints once your keys are accepted; a wrong key never gets that far. So it's not your keys — it's the part after connecting, which is on our side. You can also skip the install-and-test steps Tom AI suggested (installing wireguard tools, hand-editing a wg0.conf file) — on a WSL box those won't tell us anything new and can tangle things up. One thing I want to confirm before I hand this to Tom: did sudo sparkbox refresh-vpn-servers from my last reply actually run? It grabs today's Proton server list and restarts the media apps — the fix for exactly this "connected but nothing gets through" state. If it ran and it still loops, say the word and I'll pass your full log to Tom now.
Zypherdose wrote:
i ran that command was it supposed to download a list i can read somehwhere or is it a list for itself? Windows PowerShell Copyright (C) Microsoft Corporation. All rights reserved. Try the new cross-platform PowerShell https://aka.ms/pscore6 PS C:\Windows\system32 wsl -d sparkbox wsl: DNS Tunneling is not supported root@TV-Server:/mnt/c/Windows/system32 sudo sparkbox refresh-vpn-servers / | | | | ) \ \| ' \ / | '| |/ / \ / \ \/ / ) | |) | (| | | | <| |) | () < |/| ./ \,|| ||\\/ \//\\ || SparkBox v1.6.612 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private Refresh the VPN's server list Downloads a current copy of your VPN provider's server list. Fixes the case where the VPN says it's connected but nothing actually goes through it, because the saved list points at servers whose keys your provider has since changed. [INFO] Asking protonvpn for a current server list (this runs outside the VPN)... [OK] Server list refreshed for protonvpn. [INFO] Restarting the media apps so the VPN picks up the new list... [INFO] Tailscale is on — allowing the tailnet range (redacted) back out of the VPN tunnel so the apps behind it answer remotely. [INFO] Restarting module: media (recreating to pick up .env changes) WARN[0000] Found orphan containers (sb-tailscale, sb-dashboard, sb-npm, sb-portainer, sb-homepage) for this project. If you removed or renamed this service in your compose file, you can run this command with the --remove-orphans flag to clean it up. [+] up 3/14 ✘ Contain... Error response from daemon: Error when allocating new name: Conflict. The container name "/sb-bazarr" is already in use by container "redacted". You have to remove (or rename) that container to be able to reuse that name. 0.3s 0.2s ⠹ Contain... Stopping 0.3s ✔ Contain... Recreated 0.3s ⠹ Contain... Recreate 0.3s ⠹ Contain... Recreate 0.3s ✔ Contain... Recreated 0.2s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s ⠋ Contain... Recreate 0.0s Error response from daemon: Error when allocating new name: Conflict. The container name "/sb-bazarr" is already in use by container "redacted". You have to remove (or rename) that container to be able to reuse that name. [WARN] Some apps were created but never started (a dependency — usually the VPN tunnel — wasn't healthy in time). Starting them now: [OK] started jellyfin-media [OK] started seerr [OK] started deunhealth [OK] started gluetun [ERROR] These apps are still NOT running: chaptarr qbittorrent sabnzbd sonarr radarr lidarr flaresolverr prowlarr [ERROR] They ride on the VPN tunnel and can't start until it's healthy. [ERROR] Check what's wrong: sudo sparkbox doctor [ERROR] Then bring them up: sudo sparkbox restart media [ERROR] Restart did NOT finish cleanly — some apps may not be running. [ERROR] Check: sudo sparkbox status [ERROR] Diagnose: sudo sparkbox doctor root@TV-Server:/mnt/c/Windows/system32 sudo sparkbox refresh-vpn-servers / | | | | ) \ \| ' \ / | '| |/ / \ / \ \/ / ) | |) | (| | | | <| |) | () < |/| ./ \,|| ||\\/ \//\\ || SparkBox v1.6.612 - Self-Hosted Privacy Stack Created by Tom Spark | youtube.com/@TomSparkReviews Network profile: private Refresh the VPN's server list Downloads a current copy of your VPN provider's server list. Fixes the case where the VPN says it's connected but nothing actually goes through it, because the saved list points at servers whose keys your provider has since changed. [INFO] Asking protonvpn for a current server list (this runs outside the VPN)... [OK] Server list refreshed for protonvpn. [INFO] Restarting the media apps so the VPN picks up the new list... [INFO] Tailscale is on — allowing the tailnet range (redacted) back out of the VPN tunnel so the apps behind it answer remotely. [INFO] Restarting module: media (recreating to pick up .env changes) WARN[0000] Found orphan containers (sb-tailscale, sb-dashboard, sb-npm, sb-portainer, sb-homepage) for this project. If you removed or renamed this service in your compose file, you can run this command with the --remove-orphans flag to clean it up. [+] up 5/144 ✔ Container f7c6bb3b89e8sb-bazarr Recreated 0.2s ✔ Container sb-seerr Started 2.3s ✔ Container sb-jellyfin-media Started 2.3s ✔ Container sb-deunhealth Started 2.1s ⠴ Container sb-gluetun Waiting 113.9s ⠸ Container sb-chaptarr Starting 112.4s ⠸ Container sb-sabnzbd Starting 112.4s ⠹ Container sb-prowlarr Starting 112.4s ⠸ Container sb-lidarr Starting 112.4s ⠸ Container sb-radarr Starting 112.4s ⠸ Container sb-sonarr Starting 112.4s ⠸ Container sb-qbittorrent Starting 112.4s ⠸ Container sb-flaresolverr Starting 112.4s ✔ Container sb-bazarr Started 0.4s ^C^C root@TV-Server:/mnt/c/Windows/system32 then it kept loading with the logs of glutun looping this: will post next comment due to draft limit...
Zypherdose wrote:
check the comment above 2026-08-23T09:26:40+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout 2026-08-23T09:26:40+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T09:26:40+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T09:26:40+04:00 INFO [vpn] stopping 2026-08-23T09:26:40+04:00 INFO [vpn] starting 2026-08-23T09:26:40+04:00 INFO [firewall] allowing VPN connection... 2026-08-23T09:26:41+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-23T09:26:41+04:00 INFO [wireguard] Connecting to redacted 2026-08-23T09:26:41+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-23T09:26:47+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-23T09:26:47+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T09:26:47+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T09:26:47+04:00 INFO [vpn] stopping 2026-08-23T09:26:47+04:00 INFO [vpn] starting 2026-08-23T09:26:47+04:00 INFO [firewall] allowing VPN connection... 2026-08-23T09:26:47+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-23T09:26:47+04:00 INFO [wireguard] Connecting to redacted 2026-08-23T09:26:47+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-23T09:26:54+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup github.com: i/o timeout, parallel attempt 2/2 failed: dialing: dial tcp4: lookup cloudflare.com: i/o timeout 2026-08-23T09:26:54+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T09:26:54+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T09:26:54+04:00 INFO [vpn] stopping 2026-08-23T09:26:54+04:00 INFO [vpn] starting 2026-08-23T09:26:54+04:00 INFO [firewall] allowing VPN connection... 2026-08-23T09:26:54+04:00 INFO [wireguard] Using available kernelspace implementation 2026-08-23T09:26:54+04:00 INFO [wireguard] Connecting to redacted 2026-08-23T09:26:54+04:00 INFO [wireguard] Wireguard setup is complete. Note Wireguard is a silent protocol and it may or may not work, without giving any error message. Typically i/o timeout errors indicate the Wireguard connection is not working. 2026-08-23T09:26:58+04:00 WARN Caught OS signal terminated, shutting down 2026-08-23T09:26:58+04:00 INFO dns ticker: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO updater ticker: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO http server: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO control: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO updater: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO tickers: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO HTTP health server: terminated ✔️ 2026-08-23T09:26:58+04:00 WARN [vpn] restarting VPN because it failed to pass the healthcheck: startup check: all check tries failed: parallel attempt 1/2 failed: dialing: dial tcp4: lookup cloudflare.com: operation was canceled, parallel attempt 2/2 failed: dialing: dial tcp4: lookup github.com: operation was canceled 2026-08-23T09:26:58+04:00 INFO [vpn] 👉 See https://github.com/qdm12/gluetun-wiki/blob/main/faq/healthcheck.md 2026-08-23T09:26:58+04:00 INFO [vpn] DO NOT OPEN AN ISSUE UNLESS YOU HAVE READ AND TRIED EVERY POSSIBLE SOLUTION 2026-08-23T09:26:58+04:00 INFO vpn: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO shadowsocks proxy: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO dns: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO http proxy: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO other: terminated ✔️ 2026-08-23T09:26:58+04:00 INFO [routing] routing cleanup... 2026-08-23T09:26:58+04:00 INFO [routing] default route found: interface eth0, gateway redacted and family v4 2026-08-23T09:26:58+04:00 INFO [routing] deleting route for redacted 2026-08-23T09:26:58+04:00 INFO [routing] deleting route for redacted 2026-08-23T09:26:58+04:00 INFO [routing] deleting route for redacted 2026-08-23T09:26:58+04:00 INFO [routing] deleting route for redacted 2026-08-23T09:26:58+04:00 INFO [routing] deleting route for redacted @@@ @@@@ @@@@@@ @@@@.@@ @@@@@@@@@@ @@@@.@@@ @@@@@@@@==@@@@ @@@.@..@@ @@@@@@@=@..==@@@@ @@@@ @@@.@@.@@ @@@@@@===@@@@.=@@@ @...-@@ @@@@.@@.@@@ @@@ @@@@@@=======@@@=@@@@ @@@@@@@@ @@@.-%@.+@@@@@@@@ @@@@@%============@@@@ @@@.--@..@@@@.-@@@@@@@==============@@@@ @@@@ @@@-@--@@.@@.---@@@@@==============@@@@@ @@@ @@@.@@-@@.@@--@@@@@===============@@@@@@ @@@@.@--@@@@@@@@@@================@@@@@@@ @@@..--@@@@@@@@================@@@@+@@ @@@.---@@.@@@@=================@@@@--@@ @@@-.---@@@@@@================@@@@--@@@ @@@.:-@@@@@@===============@@@@.---@@ @@@.-------.@@@============@@@@@@.--@@@ @@@..--------:@@@=========@@@@@@@@.--@@@ @@@.-@@@@@@@@@@@========@@@@@ @@@.--@@ @@.@@@@===============@@@@@ @@@@@@---@@@@@@ @@@@@@@==============@@@@@@@@@@@@@---@@@@@@@@ @@@@@@=============@@@@@ @@@...------------.@@@ @@@@%===========@@@@@@ @@@..------@@@@.-----.-@@@ @@@@@@.=======@@@@@@ @@@.-------@@@@@@-.------=@@ @@@@@@@@@===@@@@@@ @@.------@@@@ @@@@.-----@@@ @@@==@@@=@@@@@@@ @@@.-@@@@@@@ @@@@@@@--@@ @@@@@@@@@@@@@ @@@@@@@@ @@@@@@@ @@@@@@@@ @@@@ @@@@ 2026-08-23T09:26:58+04:00 INFO Shutdown successful root@TV-Server:/mnt/c/Windows/system32 btw is there a way to get glutun to stop putting the swan @@@@ image when diagnosing its a pain in the ass when reading or sharing logs... who thought this was a good idea
Chris wrote:
It's a list for itself — good instinct to check. The refresh-vpn-servers command saves the fresh Proton server list inside SparkBox where gluetun reads it, so there's no file for you to open. The line that matters is the one you already got: [OK] Server list refreshed for protonvpn. That means the download worked. The new log is the real story. The tunnel connects, but then it can't actually reach the internet through it — the cloudflare and github checks time out — and that's what keeps tripping the restart loop. The refresh ruled out the stale-list cause, so this is the needs-Tom case I mentioned. I've passed your full log to Tom, and there's nothing more for you to run right now. On the swan: that's gluetun's own startup banner, not something SparkBox draws, so there's no switch for it. I know it's a pain when pasting logs.